Junglewise Threat Intelligence

CVE-2026-14130: Google Chrome UI spoofing in Omnibox

CVE-2026-14130 · Severity: info · CVSS 3.1 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the address bar (Omnibox) could allow a malicious website to display misleading security information or fake web addresses. This could be used in phishing attacks to trick users into believing they are on a legitimate site when they are actually on a malicious one.

Technical details

An incorrect security UI implementation in the Omnibox component of Google Chrome allowed for UI spoofing. A remote attacker could exploit this by enticing a user to visit a specially crafted HTML page. If successful, the attacker could misrepresent the origin or security status of the page shown in the address bar. This issue affected Google Chrome versions prior to 150.0.7871.47 and has been addressed in the stable channel update.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats